fix(active-content): raw-html graded two inert shapes HIGH, and the fix moved a second surface
`is_active_tag`'s URL-attribute branch was a presence test: any element carrying `href=`/`src=`/`action=` graded HIGH regardless of where the URL pointed. An MDX `<Card href="/en/agent-sdk/quickstart">` reaches no attacker-controlled host, and neither does APIM policy XML's `<set-header>`. It now requires an external target -- the rule the markdown paths have applied since 0.3.1. `<base>` left the active name set in the same change: HTML's `<base>` has its whole affordance in an `href` the attribute branch still catches, and APIM's attribute-less `<base />` is inert. Measured before and after in ONE session against one corpus state, because two of the three corpora are living and a split would mix this with re-harvest drift: reference-corpus 389 docs 133 -> 108 (ceiling 107) vendor-harvest 187 docs 100 -> 98 (ceiling 62) generated-notes 550 docs 90 -> 88 (ceiling 49) 96% of the achievable reduction in reference-corpus, 5% in the wiki corpora. The two classes had to be measured TOGETHER -- alone they free 3 and 13 documents, together 25, because a document carrying one usually carries the other. The second surface: `neutralize` imported `is_active_tag` by name, so this would have silently narrowed the opt-in mutator too -- and no test discriminated the two halves, since every `neutralize:raw-html` payload stays active under any narrowing considered. That test is written first here. The predicates are now separate symbols; the mutator keeps defanging anything, because over-defanging is auditable and blocks nothing while under-defanging hands a human a live construct. Behaviour change: a document whose only finding was one of these classes now WARNs instead of holding. Detection is unchanged -- 128/128 classes, 6/6 gaps hold. Self-safety: reading an attribute VALUE needs a pattern the presence test lacks. It reuses the same literal alternation so no new run shape enters the table; its `_REDOS_PAYLOADS` row denies the `=` the pattern requires, since a unit supplying it matches at once and never exercises the run (the lexicon's `script-tag` row is the cautionary case). 0.031-0.046s across five attack shapes at 100_000 chars against a 2.0s bound; `docs/redos-sweep.py` reports 0 candidates of 152. An attribute the presence test saw but the value parser cannot read counts as external -- fail secure. `docs/rawhtml-census.py` gains a PRODUCTION row that re-measures the shipped predicate rather than a hypothesis, so a published number and the code cannot drift apart unnoticed. README's limitation count moves 34 -> 33. 727 passed (was 717).
This commit is contained in:
parent
e671edb96f
commit
736f370cfb
9 changed files with 287 additions and 72 deletions
|
|
@ -13,6 +13,8 @@ The transform is pure ``text -> (defanged_text, report)`` — no I/O, no globals
|
|||
"""
|
||||
import time
|
||||
|
||||
import pytest
|
||||
|
||||
from llm_ingestion_guard.neutralize import neutralize
|
||||
from llm_ingestion_guard.report import Severity, Source
|
||||
|
||||
|
|
@ -97,6 +99,27 @@ def test_raw_active_html_is_escaped():
|
|||
assert html[0].severity is Severity.HIGH
|
||||
|
||||
|
||||
@pytest.mark.parametrize("cid,text", [
|
||||
("relative-href-on-inactive-name", '<Card href="/en/agent-sdk/quickstart">'),
|
||||
("attributeless-base", "<base />"),
|
||||
])
|
||||
def test_mutator_still_defangs_what_the_scanner_now_lets_pass(cid, text):
|
||||
# The deliberate asymmetry, extended to raw HTML in 0.6.0: the SCANNER narrowed
|
||||
# its URL-attribute branch to external targets and dropped `<base>` from the name
|
||||
# set; the opt-in MUTATOR keeps defanging anything. Over-defanging costs nothing
|
||||
# here — it is auditable and blocks no disposition — while under-defanging would
|
||||
# hand a human a live construct.
|
||||
#
|
||||
# Pinned because the two predicates are separate symbols as of this change
|
||||
# (`is_active_tag` vs `is_defangable_tag`). Before the split, `neutralize`
|
||||
# imported the scanner's predicate by name, so narrowing it would have moved the
|
||||
# mutator silently — no test in this suite discriminated the two.
|
||||
result = neutralize(text)
|
||||
assert result.report.found is True, cid
|
||||
assert any(f.label == "neutralize:raw-html" for f in result.report.findings), cid
|
||||
assert "<" in result.text, f"{cid}: not escaped -- {result.text!r}"
|
||||
|
||||
|
||||
def test_benign_formatting_html_is_left_untouched():
|
||||
text = "This is **bold** and <b>strong</b> and <em>emph</em> text."
|
||||
result = neutralize(text)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue